CVE-2024-47270
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.
Scoring
- Severity
- LOW
- CVSS base score
- 2.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-281
- Published
- 2026-05-27
- Last modified
- 2026-05-27
Affected products
- Synology Surveillance Station
Weakness type
Related vulnerabilities
- CVE-2026-88016 — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2025-14779 — Improper Access Control via Secret Type Management API in WSO2 Identity Server
- CVE-2026-23556 — oxenstored keeps quota related use counts across domain destruction
- CVE-2026-58494 — Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
- CVE-2026-4360 — Tarfile.extract() doesn't fully respect filter parameter
- CVE-2026-44947 — Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
- CVE-2026-40767 — WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability